Home News Forum Articles
  Welcome back Join CF
You are here You are here: Home | Forum | Spyware I can't seem to get rid of


You are currently viewing our boards as a guest which gives you limited access to view most of the discussions, articles and other free features. By joining our Virgin Media community you will have full access to all discussions, be able to view and post threads, communicate privately with other members (PM), respond to polls, upload your own images/photos, and access many other special features. Registration is fast, simple and absolutely free so please join our community today.


Welcome to Cable Forum
Go Back   Cable Forum > Computers & IT > General IT Discussion

Spyware I can't seem to get rid of
Reply
 
Thread Tools
Old 21-02-2004, 22:08   #1
Bifta
!
 
Join Date: Jul 2003
Location: Eglinton, Co. Derry
Posts: 7,640
Bifta has a nice shiny starBifta has a nice shiny star
Bifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny star
Spyware I can't seem to get rid of

I have some malware that's altering my registry at the moment, istsvc, it alters some registry key (see attached) despite me removing it. I run Ad-aware pro with the latest reference file and it detects it, claims to remove it, but if I run another scan straight away, it finds it again, regardless of whether a browser is open or not, I then tried Spybot with the latest updates it didn't even detect it, how do I get rid of it? (it's not picked up by Avast either).
Bifta is offline   Reply With Quote
Advertisement
Old 21-02-2004, 22:12   #2
stuartbe
Guest
 
Location: Luton
Services: NTL Nafband
Posts: n/a
Re: Spyware I can't seem to get rid of

Quote:
Originally Posted by Bifta
I have some malware that's altering my registry at the moment, istsvc, it alters some registry key (see attached) despite me removing it. I run Ad-aware pro with the latest reference file and it detects it, claims to remove it, but if I run another scan straight away, it finds it again, regardless of whether a browser is open or not, I then tried Spybot with the latest updates it didn't even detect it, how do I get rid of it? (it's not picked up by Avast either).
Its something starting up from the registery.

Run Regedit and check..

Hkey local machine / software / microsoft windows / current version / run

HTH

Edit : It may not be spyware - Adaware pro often false alarms !!
  Reply With Quote
Old 21-02-2004, 22:13   #3
Ramrod
[NTHW] pc clan
 
Ramrod's Avatar
 
Join Date: Jun 2003
Location: Tonbridge
Age: 45
Services: Be*Pro ADSL2+
Posts: 19,702
Ramrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver bling
Ramrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver bling
Re: Spyware I can't seem to get rid of

What effect does it have when it alters the registry?
__________________
Step by step, walk the thousand mile road...
-----------------------------------------------------

nthwgaming.co.uk
Ramrod is offline   Reply With Quote
Old 21-02-2004, 22:14   #4
Bifta
!
 
Join Date: Jul 2003
Location: Eglinton, Co. Derry
Posts: 7,640
Bifta has a nice shiny starBifta has a nice shiny star
Bifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny star
Re: Spyware I can't seem to get rid of

Quote:
Originally Posted by stuartbe
Its something starting up from the registery.

Run Regedit and check..

Hkey local machine / software / microsoft windows / current version / run

HTH

Edit : It may not be spyware - Adaware pro often false alarms !!
I know that!!! The ad watch thing show's it trying to install the registry key, but I can't find where the remove the program that's actually doing it, it's not under c:/program files/ and it's not hidden either .. very confused
Bifta is offline   Reply With Quote
Old 21-02-2004, 22:15   #5
Bifta
!
 
Join Date: Jul 2003
Location: Eglinton, Co. Derry
Posts: 7,640
Bifta has a nice shiny starBifta has a nice shiny star
Bifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny star
Re: Spyware I can't seem to get rid of

Quote:
Originally Posted by Ramrod
What effect does it have when it alters the registry?
It then alters my default homepage to some crappy search engine.
Bifta is offline   Reply With Quote
Old 21-02-2004, 22:16   #6
homealone
Guest
 
Posts: n/a
Re: Spyware I can't seem to get rid of

Quote:
Originally Posted by Bifta
I have some malware that's altering my registry at the moment, istsvc, it alters some registry key (see attached) despite me removing it. I run Ad-aware pro with the latest reference file and it detects it, claims to remove it, but if I run another scan straight away, it finds it again, regardless of whether a browser is open or not, I then tried Spybot with the latest updates it didn't even detect it, how do I get rid of it? (it's not picked up by Avast either).
jv16 power tools is good for removing stuff from the registry - you have to pay for the 'later' versions, though?
  Reply With Quote
Old 21-02-2004, 22:17   #7
Bifta
!
 
Join Date: Jul 2003
Location: Eglinton, Co. Derry
Posts: 7,640
Bifta has a nice shiny starBifta has a nice shiny star
Bifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny star
Re: Spyware I can't seem to get rid of

Quote:
Originally Posted by homealone
jv16 power tools is good for removing stuff from the registry - you have to pay for the 'later' versions, though?
I can delete the registry key through regedt32 but it keeps altering the registry automatically and sticks the key back in
Bifta is offline   Reply With Quote
Old 21-02-2004, 22:17   #8
stuartbe
Guest
 
Location: Luton
Services: NTL Nafband
Posts: n/a
Re: Spyware I can't seem to get rid of

Quote:
Originally Posted by Bifta
I know that!!! The ad watch thing show's it trying to install the registry key, but I can't find where the remove the program that's actually doing it, it's not under c:/program files/ and it's not hidden either .. very confused
Have you searched for the file name in regedit ?
  Reply With Quote
Old 21-02-2004, 22:20   #9
Ramrod
[NTHW] pc clan
 
Ramrod's Avatar
 
Join Date: Jun 2003
Location: Tonbridge
Age: 45
Services: Be*Pro ADSL2+
Posts: 19,702
Ramrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver bling
Ramrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver bling
Re: Spyware I can't seem to get rid of

Thought so, this may be of use
__________________
Step by step, walk the thousand mile road...
-----------------------------------------------------

nthwgaming.co.uk
Ramrod is offline   Reply With Quote
Old 21-02-2004, 22:21   #10
Bifta
!
 
Join Date: Jul 2003
Location: Eglinton, Co. Derry
Posts: 7,640
Bifta has a nice shiny starBifta has a nice shiny star
Bifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny star
Re: Spyware I can't seem to get rid of

Quote:
Originally Posted by stuartbe
Have you searched for the file name in regedit ?
I've removed all entries for it, there's something installed that readding the key though.
Bifta is offline   Reply With Quote
Old 21-02-2004, 22:24   #11
homealone
Guest
 
Posts: n/a
Re: Spyware I can't seem to get rid of

Quote:
Originally Posted by Bifta
I can delete the registry key through regedt32 but it keeps altering the registry automatically and sticks the key back in
jv16 has been good for me during an ATI multimedia card install, - I'm biased - but given the rate of £ against the $ ? :pp
  Reply With Quote
Old 21-02-2004, 22:25   #12
stuartbe
Guest
 
Location: Luton
Services: NTL Nafband
Posts: n/a
Re: Spyware I can't seem to get rid of

Have you searched the hdd for the file.... It may be a driver of some sort that is installing it !
  Reply With Quote
Old 21-02-2004, 22:26   #13
Bifta
!
 
Join Date: Jul 2003
Location: Eglinton, Co. Derry
Posts: 7,640
Bifta has a nice shiny starBifta has a nice shiny star
Bifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny starBifta has a nice shiny star
Re: Spyware I can't seem to get rid of

Quote:
Originally Posted by homealone
jv16 has been good for me during an ATI multimedia card install, - I'm biased - but given the rate of £ against the $ ? :pp
Ummmm, deleting the registry keys isn't cutting it, they're getting re-added as fast as I can delete them.
Bifta is offline   Reply With Quote
Old 21-02-2004, 22:27   #14
stuartbe
Guest
 
Location: Luton
Services: NTL Nafband
Posts: n/a
Re: Spyware I can't seem to get rid of

Quote:
Originally Posted by Bifta
Ummmm, deleting the registry keys isn't cutting it, they're getting re-added as fast as I can delete them.
There is allways deltree /y *.* --- No dont do that
  Reply With Quote
Old 21-02-2004, 22:31   #15
Ramrod
[NTHW] pc clan
 
Ramrod's Avatar
 
Join Date: Jun 2003
Location: Tonbridge
Age: 45
Services: Be*Pro ADSL2+
Posts: 19,702
Ramrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver bling
Ramrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver blingRamrod has a lot of silver bling
Re: Spyware I can't seem to get rid of

Have you looked through that link?
__________________
Step by step, walk the thousand mile road...
-----------------------------------------------------

nthwgaming.co.uk
Ramrod is offline   Reply With Quote
Reply


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


Google Search




All times are GMT. The time now is 04:44.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
Copyright © 2003 - 2012, Cable Forum.
(server5.cableforum.co.uk)

SEO by vBSEO 3.3.2